Security at ZiaPilot AI

Last updated June 6, 2026

We take protecting your data and your customers' data seriously. Here's how we keep the platform secure.

01Encryption

All traffic is encrypted in transit with TLS. Sensitive credentials such as API keys and integration tokens are encrypted at rest.

02Tenant isolation

Every restaurant workspace is isolated with its own scoped data boundary, so one account can never read another account's conversations, customers, or settings.

03Access control

Dashboard access is protected by authenticated sessions with role-based permissions. Internal access to production data is restricted, logged, and granted on a least-privilege basis.

  • Role-based admin and staff permissions.
  • Audit logging of sensitive actions.
  • Rate limiting and security headers on every request.

04Payments

Payments are handled by Stripe, a PCI-DSS Level 1 provider. We never store full card numbers on our servers.

05Reliability & backups

Data is backed up regularly and the platform is monitored for availability and anomalies so issues are caught early.

06Responsible disclosure

Found a vulnerability? We appreciate responsible disclosure. Email [email protected] with details and we'll investigate promptly.

Questions about this page? Email [email protected] and we'll get back to you.

Turn chats into catering orders

Start a 7-day full trial (no card needed). See ZiaPilot AI answer menu questions and capture orders on your site and WhatsApp.